← Home

@teambit/preview

28
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern rapid-publish AI (publish-pattern): Monorepo lockstep publishing across many @teambit packages; benign pattern. ai
semgrep semgrep:new-function-constructor AI (semgrep): Bundled webpack UI artifact, not obfuscated malicious code. ai
provenance no-provenance AI (provenance): Stable across versions; provenance absence is a best-practice gap, not a security defect. ai
npm-metadata no-description AI (npm-metadata): Established package; missing description is cosmetic, not a malware signal. ai
source-diff obfuscated-file:artifacts/ui-bundle/static/js/main.b1c18cda.cjs AI (source-diff): Webpack-bundled UI preview asset from stated build tooling migration, not obfuscation. ai
source-diff net-exec-file:artifacts/ui-bundle/static/js/main.b1c18cda.cjs AI (source-diff): Bundled browser UI code (floating-ui etc.), no evidence of dropper behavior. ai
source-diff net-exec-file:artifacts/ui-bundle/static/js/main.b8138457.cjs AI (source-diff): Bundled UI code naturally contains fetch + dynamic module exec patterns; no exfil destination found. ai
source-diff obfuscated-file:artifacts/ui-bundle/static/js/main.b8138457.cjs AI (source-diff): Webpack/rspack bundled UI preview artifact, not obfuscation; standard for this package's build output. ai
source-diff obfuscated-file:artifacts/ui-bundle/static/js/main.72286528.cjs AI (source-diff): Webpack-bundled UI preview artifact; minified, not obfuscated malware. ai
source-diff net-exec-file:artifacts/ui-bundle/static/js/main.72286528.cjs AI (source-diff): Bundled dev-server/webpack client code, not a dropper. ai
source-diff obfuscated-file:artifacts/ui-bundle/static/js/main.58bd9271.cjs AI (source-diff): Standard rspack/webpack UI bundle artifact; minified but not obfuscated, readable class names visible in sample. ai
source-diff net-exec-file:artifacts/ui-bundle/static/js/main.58bd9271.cjs AI (source-diff): UI bundle legitimately contains fetch calls and dynamic requires; not dropper behavior. ai
dependencies unvetted-dep:@teambit/react.webpack.react-webpack AI (dependencies): First-party teambit package; consistent with the rest of the teambit dependency graph for this package. ai
source-diff net-exec-file:artifacts/ui-bundle/static/js/main.02752e96.cjs AI (source-diff): Network+exec pattern in a UI bundle is expected for a preview renderer; not dropper behavior. ai
source-diff obfuscated-file:artifacts/ui-bundle/static/js/main.02752e96.cjs AI (source-diff): Standard rspack/webpack UI bundle artifact; minified but not obfuscated, readable class names visible in sample. ai
dependencies unvetted-dep:@teambit/preview.cli.dev-server-events-listener AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai
dependencies unvetted-dep:@teambit/react AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai
dependencies unvetted-dep:@teambit/toolbox.path.to-windows-compatible-path AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai
dependencies unvetted-dep:@teambit/rspack.modules.generate-asset-manifest AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai
dependencies unvetted-dep:@teambit/harmony AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai
dependencies unvetted-dep:@teambit/bit-error AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai
dependencies unvetted-dep:@teambit/component-id AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai
dependencies unvetted-dep:@teambit/legacy.constants AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai
dependencies unvetted-dep:@teambit/component.sources AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai
dependencies unvetted-dep:@teambit/toolbox.path.path AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai
dependencies unvetted-dep:@teambit/toolbox.crypto.sha1 AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai
dependencies unvetted-dep:@teambit/mdx.modules.mdx-v3-options AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai
dependencies unvetted-dep:@teambit/preview.ui.component-preview AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai
dependencies unvetted-dep:@teambit/harmony.modules.feature-toggle AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai
dependencies unvetted-dep:@teambit/preview.modules.preview-modules AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai
dependencies unvetted-dep:@teambit/preview.cli.webpack-events-listener AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai
dependencies unvetted-dep:@teambit/ui-foundation.ui.pages.static-error AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai
dependencies unvetted-dep:@teambit/harmony.modules.harmony-root-generator AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. ai

Versions (showing 28 of 28)

Version Deps Published
1.0.1070 56 / 11
1.0.1064 56 / 11
1.0.1055 56 / 11
1.0.1054 56 / 11
1.0.1052 56 / 11
1.0.1051 56 / 11
1.0.1029 56 / 11
1.0.1021 56 / 11
1.0.1018 56 / 11
1.0.1008 56 / 11
1.0.1000 56 / 11
1.0.999 56 / 11
1.0.992 56 / 11
1.0.989 56 / 11
1.0.988 56 / 11
1.0.986 56 / 11
1.0.972 56 / 11
1.0.971 56 / 11
1.0.970 56 / 11
1.0.968 56 / 11
1.0.927 56 / 11
1.0.915 56 / 11
1.0.810 52 / 12
1.0.323 44 / 14
1.0.318 43 / 14
1.0.279 43 / 14
1.0.262 43 / 14
1.0.258 43 / 14

v1.0.1070

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1064

3 findings
HIGH New obfuscated file: artifacts/ui-bundle/static/js/main.72286528.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/ui-bundle/static/js/main.72286528.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1055

3 findings
HIGH New obfuscated file: artifacts/ui-bundle/static/js/main.b8138457.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/ui-bundle/static/js/main.b8138457.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1054

3 findings
HIGH New obfuscated file: artifacts/ui-bundle/static/js/main.b8138457.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/ui-bundle/static/js/main.b8138457.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1052

3 findings
HIGH New obfuscated file: artifacts/ui-bundle/static/js/main.b8138457.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/ui-bundle/static/js/main.b8138457.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1051

3 findings
HIGH New obfuscated file: artifacts/ui-bundle/static/js/main.b8138457.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/ui-bundle/static/js/main.b8138457.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.915

3 findings
HIGH New obfuscated file: artifacts/ui-bundle/static/js/main.b1c18cda.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/ui-bundle/static/js/main.b1c18cda.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.323

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.318

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.279

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.262

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.258

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.